CVE-2022-2647: jeecg-boot unrestricted upload
Published Aug 4, 2022
·Updated
A vulnerability was found in jeecg-boot. It has been declared as critical. This vulnerability affects unknown code of the file /api/. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-205594 is the identifier assigned to this vulnerability.
Affected Software
1 affected component
Jeecg jeecg boot
Event History
Aug 4, 2022
CVE Published
via MITRE·08:41 AM
Data Sourced
via MITRE·08:41 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2647?
The severity of CVE-2022-2647 is critical.
2
How does CVE-2022-2647 affect Jeecg Boot?
CVE-2022-2647 affects Jeecg Boot by allowing unrestricted file upload through a manipulated argument.
3
Can CVE-2022-2647 be exploited remotely?
Yes, CVE-2022-2647 can be exploited remotely.
4
How can I fix CVE-2022-2647?
To fix CVE-2022-2647, it is recommended to apply the latest security patch provided by jeecg-boot.
5
What is the Common Weakness Enumeration (CWE) for CVE-2022-2647?
The CWE for CVE-2022-2647 is CWE-434.